2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site scripting due to improper headers in direct access to uploaded SVGs. The application allows uploading images in several places. One of the accepted types of image is SVG, which allows JS scripting. Therefore, by uploading a malicious SVG which contains JS code, an attacker which is able to drive a victim to the uploaded image could compromise that victim's session and access to their tokens. Version 5.4.1 contains a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bubka
Bubka 2fauth |
|
CPEs | cpe:2.3:a:bubka:2fauth:*:*:*:*:*:*:*:* | |
Vendors & Products |
Bubka
Bubka 2fauth |
|
Metrics |
ssvc
|
Wed, 20 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site scripting due to improper headers in direct access to uploaded SVGs. The application allows uploading images in several places. One of the accepted types of image is SVG, which allows JS scripting. Therefore, by uploading a malicious SVG which contains JS code, an attacker which is able to drive a victim to the uploaded image could compromise that victim's session and access to their tokens. Version 5.4.1 contains a patch for the issue. | |
Title | 2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render | |
Weaknesses | CWE-79 CWE-80 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-20T14:01:37.062Z
Updated: 2024-11-20T14:31:57.628Z
Reserved: 2024-11-14T15:05:46.770Z
Link: CVE-2024-52597
Vulnrichment
Updated: 2024-11-20T14:31:48.441Z
NVD
Status : Awaiting Analysis
Published: 2024-11-20T14:15:17.967
Modified: 2024-11-21T13:57:24.187
Link: CVE-2024-52597
Redhat
No data.